Re: Firescrolling [Firefox 1.0]

From: Brian Bergin (ntbugtraq.nospam.1_at_TERABYTE.NET)
Date: 02/25/05

  • Next message: Russ: "Re: Firescrolling [Firefox 1.0]"
    Date:         Fri, 25 Feb 2005 11:29:16 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    At 03:10 25-02-05 Friday, you wrote:
    >Remember my Internet Explorer "scrollbar exploit" based on http-equiv's
    >"What a Drag"? When will people ever learn that "unusual user interaction"
    >can be hidden by common tasks...
    >
    >Let's combine fireflashing, firetabbing, xul and javascript to run arbitrary
    >code by dragging a scrollbar two times.
    >
    >__Proof-of-Concept
    >
    >http://www.mikx.de/firescrolling/
    >
    >__Status
    >
    >The exploit is based on multiple vulnerabilities:
    >
    >bugzilla.mozilla.org #280664 (fireflashing)
    >bugzilla.mozilla.org #280056 (firetabbing)
    >bugzilla.mozilla.org #281807 (firescrolling)
    >
    >Upgrade to Firefox 1.0.1 or disable javascript.
    >
    >The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    >assigned the name CAN-2005-0527 to this issue.

    Mozilla has apparently decided to delay, to the detriment of its users, the
    auto-update feature of Firefox 1.0 so that getting 1.0.1 out there, unless
    someone actually looks for updates manually on mozilla.org, will be delayed
    several days. These fixes have been a long time coming and to delay them
    to the general user any longer is a disservice, IMHO.

    I would encourage Mozilla to reconsider this delay and get the update out
    there ASAP via the auto-update feature.

    NOTE: Please reply to the list so others may benefit from your
    thoughts. If you're concerned it may not make it to the list, please cc:
    me on the reply.

    Sincerely,
    Terabyte Computers, Inc.

    Brian S. Bergin
    President

    http://www.terabyte.net

    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    --
    

  • Next message: Russ: "Re: Firescrolling [Firefox 1.0]"

    Relevant Pages

    • Re: Staging Question
      ... Yes, I've noticed that we have a lot in common, Nick. ... Have you ever tried using time alignment to add delay to the RIGHT ... of TA because whenever I added delay to the left speakers I could never seem ... Everyone please feel free to technical "blah blah blah" me to death about ...
      (rec.audio.car)
    • Re: CPU Creating Objects vs Modifying Object Properties
      ... dhtml writes: ... "two thread" inference, the two will never call the function at the ... The delay between calls will, in theory, be one of 20ms, 10ms or 0ms. ... That's because javascript is always single-threaded. ...
      (comp.lang.javascript)
    • Re: {OT} the party of obstruction
      ... DeLay seemed to be pretty effective at getting the Republican party ... is we were not in a war then that meant our very survival. ... You libs like to think you are 'above' the common folk...but you are ... because they don't give a damn about protecting us and making Americans ...
      (alt.autos.toyota)
    • Re: how to define a local function
      ... Common Lispers just like to show the classic delay and force macro, ... if delayed evaluation is a fait accompli. ... They are typically just used to illustrate what macros can do. ...
      (comp.lang.lisp)
    • Re: store external javascript files in aspnet_client subfolder
      ... store common javascript files and other include common files. ... use of this folder by including their own subfolder under ... storing common .js files for use in custom web controls, ...
      (microsoft.public.dotnet.framework.aspnet.webcontrols)